Transition Networks
S4224 Web User Guide
33558 Rev. C
Page 102 of 669
ACL Ports Configuration
Configure the ACL parameters (ACE) of each S4224 port from the
Configuration
>
Security
>
Network
>
ACL
>
Ports
menu path. The ACL Ports Configuration parameters will affect frames received on a port
unless the frame matches a specific ACE.
Access Controls Lists
The S4224 can ‘peek’ into the frames at line rate and is capable of deep packet inspection; this ability
gives a wide range of access controls. The rules or the access control lists can look at any field in the
Layer 2 to Layer 4 headers to make the decision of allowing, discarding, mirroring, logging or even
shutdown the port that the frame came through.
The ACL rule created can be associated with any port as well when created as a policy.
Apart from the ACL, there is a device level option to do storm prevention for the unicast, multicast and
broadcast frames.
ACE (Access Control Entry) describes access permissions associated with a particular ACE ID. There are
three ACE frame types (Ethernet Type, ARP, and IPv4) and two ACE actions (permit and deny). The ACE
also contains many detailed, different parameter options that are available for individual application.
The
Configuration
>
Security
>
Network
>
ACL
>
Ports
page parameters are explained below.